CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,631 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 5 of 33
- CVE-2018-13384MEDIUMCVSS 6.1EG 6.12019-06-04
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web dom…
- CVE-2018-13401MEDIUMCVSS 6.1EG 6.12018-10-23
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from…
- CVE-2018-13402MEDIUMCVSS 6.1EG 6.12018-10-23
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.…
- CVE-2018-1355MEDIUMCVSS 6.1EG 6.12018-06-27
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiVi…
- CVE-2018-13813HIGHCVSS 8.1EG 8.12018-12-13
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KT…
- CVE-2018-14366MEDIUMCVSS 6.1EG 6.12018-09-06
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
- CVE-2018-14381MEDIUMCVSS 6.1EG 6.12018-07-18
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
- CVE-2018-14398MEDIUMCVSS 6.1EG 6.12018-09-07
An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.
- CVE-2018-14474MEDIUMCVSS 6.1EG 6.12018-07-20
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
- CVE-2018-14574MEDIUMCVSS 6.1EG 6.12018-08-03
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
- CVE-2018-14658MEDIUMCVSS 6.1EG 6.12018-11-13
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
- CVE-2018-14931MEDIUMCVSS 6.1EG 6.12019-04-30
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.
- CVE-2018-15178MEDIUMCVSS 6.1EG 6.12018-08-08
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isVal…
- CVE-2018-15180MEDIUMCVSS 6.1EG 6.12019-04-02
qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
- CVE-2018-15403MEDIUMCVSS 5.4EG 5.42018-10-05
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker t…
- CVE-2018-15493MEDIUMCVSS 6.1EG 6.12018-10-17
vBulletin 5.4.3 has an Open Redirect.
- CVE-2018-15683MEDIUMCVSS 6.1EG 6.12018-09-05
An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected.
- CVE-2018-15798HIGHCVSS 7.6EG 7.62018-12-19
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website a…
- CVE-2018-16174MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2018-16191MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0.11, EC-CUBE 3.0.12, E…
- CVE-2018-1654MEDIUMCVSS 6.8EG 6.82018-12-11
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote atta…
- CVE-2018-16761MEDIUMCVSS 6.1EG 6.12018-09-09
Eventum before 3.4.0 has an open redirect vulnerability.
- CVE-2018-16954MEDIUMCVSS 6.1EG 6.12018-09-18
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated by the application …
- CVE-2018-1704MEDIUMCVSS 6.8EG 6.82018-09-28
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web si…
- CVE-2018-17074MEDIUMCVSS 6.1EG 6.12018-09-16
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
- CVE-2018-1736HIGHCVSS 7.4EG 7.42018-09-27
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulner…
- CVE-2018-17422MEDIUMCVSS 6.1EG 6.12019-03-07
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
- CVE-2018-17870MEDIUMCVSS 6.1EG 6.12018-10-01
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683.
- CVE-2018-17948MEDIUMCVSS 6.1EG 6.12018-11-20
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
- CVE-2018-18288MEDIUMCVSS 6.1EG 6.12019-12-26
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
- CVE-2018-1875HIGHCVSS 7.4EG 7.42019-03-05
IBM InfoSphere Information Governance Catalog 11.3, 11.5, and 11.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker co…
- CVE-2018-19106MEDIUMCVSS 6.1EG 6.12019-02-20
Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.
- CVE-2018-1939MEDIUMCVSS 6.8EG 6.82019-03-05
IBM Cloud Private 3.1.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the…
- CVE-2018-19790MEDIUMCVSS 6.1EG 6.12018-12-18
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms,…
- CVE-2018-19796MEDIUMCVSS 6.1EG 6.12018-12-03
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
- CVE-2018-20698MEDIUMCVSS 6.1EG 6.12019-04-09
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
- CVE-2018-20867MEDIUMCVSS 6.1EG 6.12019-07-30
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
- CVE-2018-20929MEDIUMCVSS 6.1EG 6.12019-08-01
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
- CVE-2018-2476MEDIUMCVSS 6.1EG 6.12018-11-13
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
- CVE-2018-25091MEDIUMCVSS 6.1EG 6.12023-10-15
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed t…
- CVE-2018-25245HIGHCVSS 7.5EG 7.52026-04-04
7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the sear…
- CVE-2018-3743MEDIUMCVSS 6.1EG 6.12018-06-01
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
- CVE-2018-3774CRITICALCVSS 10.0EG 10.02018-08-12
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
- CVE-2018-3819MEDIUMCVSS 6.1EG 6.12018-03-30
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an…
- CVE-2018-5304MEDIUMCVSS 4.3EG 4.32018-05-11
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the…
- CVE-2018-5548MEDIUMCVSS 6.1EG 6.12018-09-13
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using diffe…
- CVE-2018-6200MEDIUMCVSS 6.1EG 6.12018-01-25
vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.
- CVE-2018-6324MEDIUMCVSS 6.1EG 6.12018-02-16
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
- CVE-2018-6520MEDIUMCVSS 6.1EG 6.12018-02-02
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
- CVE-2018-7091MEDIUMCVSS 6.1EG 6.12018-08-06
HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →